Home / os / winnt

ManageEngine Applications Manager Authenticated Remote Code Execution

Posted on 05 September 2020

ManageEngine Applications Manager authenticated remote code execution exploit that leverages the newInstance() and loadClass() methods being used by the "WeblogicReference", when attempting a Credential Test for a new Monitor. Versions below 14720 are affected.

 

TOP